Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Directory Traversal in SPED-EFD, SAP security note 1592567

SAP Note 1592567
SAP Security Note
High priority

SAP security note 1592567, "Directory Traversal in SPED-EFD", is a program error note released on 13.09.2011. Below are the symptom and SAP recommended solution.

ComponentXX-CSC-BR-REP (Miscellaneous > Country/Region-Specific Developments > Brazil > use FI-LOC-FI-BR-REP)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on13.09.2011
LanguageEnglish

Description

Symptom

Potential Directory Traversal in SPED-EFD.

Solution

Please refer to Note 1497003 for additional information and instructions. The corrections from Note 1497003 are a prerequisite for the implementation of this note.

Logical File Name Used in this Solution: FILE_EFD_SPED

Program Using this Logical Filename: J_1BEFD_MAIN

Logical File Path Used in this Solution: FILE_EFD_SPED

Reason and prerequisites

  • The program contained in the correction instructions contains vulnerabilities through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information.
  • The program contained in the correction instructions contains a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.

References

Full note on SAP: SAP Support Launchpad note 1592567

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More